Your login is under attack.It comes protected.

Bots guess passwords against wp-login.php and XML-RPC around the clock — the most-attacked door on any WordPress site. MalCare limits the attempts, locks out the guessers, and never locks out you.

2B+ attacks blocked / mo/350K+ bots / mo/On by default
00061218

The door · last 24 hours

1,904

guesses — all stopped

wp-login.php
1,412
xmlrpc.php
492
You · 21:04
straight in

Reached wp-admin uninvited · 0

Trusted by 400,000+ sites · 120 countries
The siege

Every WordPress login is being guessed right now.

Brute force is bots trying username-password pairs until one works. The proof is already in your log — pages of failed logins that aren't yours.

4 minutes of one night's wp_login_failed records — 36 guesses from 12 addresses in that window, not one of them yours. 10 went to xmlrpc.php rather than the login form: the same flood, at the door with no login box to notice.
wp-login.php
The visible door

The most-attacked door

Password floods run around the clock, on every site.

xmlrpc.php
The second door

The door everyone forgets to guard

It accepts remote logins, and attackers flood it with passwords.

24/7
Constant pressure

It isn't personal

Every site gets the siege, and every guess burns CPU your visitors need.

The door policy

Three gates for the bots. A clear lane for your team.

Bots are blocked before their first guess, locked out after repeated failures, or stalled at a captcha. Whitelisted humans never meet any of it.

Both doors

wp-login.php and XML-RPC

The same limits and lockouts cover both.

Lockouts

You can clear a lockout in seconds. A bot can't.

Repeated failures lock anyone out — that part is the same for everyone. The recovery isn't.

  • 3.1The captcha is the keyA locked-out human passes reCAPTCHA and is back immediately — no timer, no email to your host.
  • 3.2Scripts stay outsideAn automated guesser never passes it — locked indefinitely.
  • 3.3Your team never sees itWhitelisted IPs aren't subject to lockouts at all, even after failed attempts.
Time since the lockout, measured the same way for everyone. A locked-out person clears the wall with a reCAPTCHA and is back in seconds — no timer to sit out. An automated guesser has no terminus at all: the scale breaks and its lockout keeps running off the plate. A whitelisted address never starts one.
Side by side

Three ways to limit logins, side by side.

A limiter plugin, a code snippet, or MalCare — what each one asks of you.

What it asks of youMalCareA limiter pluginA functions.php snippet
SetupNone — on when you connectRetry counts and lockout durations to pickEdit a critical theme file
Covers XML-RPCYesUsually notNo
When you're locked outPass a captcha — secondsWait out the timerFTP in and edit the file
Your teamWhitelisted — never locked outSame rules as the botsSame
MaintenanceNoneOne more plugin to update foreverLost on the next theme update — block themes don't even have the file
Cost of a mistakeNothing — recover in secondsA lockout you sit outA fatal error takes the site down
Zero setup

Login protection is on from the moment you connect. Nothing to tune.

No thresholds to pick, no lockout durations to weigh, no settings page to revisit.

Step 1

Connect your site

Install the plugin, connect it to your dashboard — protection is already running.

Step 2

Nothing to configure

No retry counts, no durations, no settings page — it's handled.

Step 3

Prove it to yourself

Log in wrong several times, fast. Watch the lockout land, pass the captcha, and walk straight back in.

Blocked login floods give you your server back.

Login floods burn CPU and bandwidth, and your real visitors feel it. Ending the flood is performance you can measure.

  • CPU and bandwidth returned to real visitors
  • Every attempt — blocked, failed, or successful — recorded in the activity log
  • Failed-login floods become visible evidence, not a mystery
  • Your team's logins, unchanged

In their words. No more sleepless nights.

Rated 5 out of 5
Best login protection ever! We handle hundreds of sites, and I'd heard bad stories about brute force attacks & password hacking… but thankfully we never had to worry about this because of MalCare. I'm sure this saved us from many sleepless nights!
Robert AbelaWP Activity Log
Rated 5 out of 5
MalCare sends few security notifications, so one day out of curiosity I checked their firewall section. I was pleasantly surprised that hundreds of attacks were being quietly thwarted! I really like this "strong & silent" protection.
Jo WalthamCallia Web
Rated 5 out of 5
I was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.
Paul LaceyWordPress Expert
Rated 5 out of 5
I had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.
Adam SilverConciergeWP · Founder
Rated 5 out of 5
Always one step ahead! Before any clients or customers have a weird experience, I get a vulnerability notification which is easily fixed with one click. Really impressed with their scanner precision!
David McCanWebTNG

Locked out right now? A real person answers.

If you can't get into wp-admin — or lockout alerts are flooding your inbox — our security team walks you through it.

24/7/Security experts/No obligation

Common questions, answered.

Repeated rapid failures trigger it — industry guidance puts the right threshold at 3–5 attempts, and MalCare handles this automatically. There's nothing for you to configure or tune.
Pass the reCAPTCHA and you're back in immediately. No waiting out a timer, no support ticket to your host — the recovery is self-serve and takes seconds.
Yes. Whitelist their IPs — whitelisted users aren't subject to lockouts, even after failed attempts. Useful for offices, agencies, and anyone who logs in daily.
Yes. XML-RPC accepts logins remotely and attackers flood it with password attempts exactly like the login form — so MalCare guards both doors, not just the one with a visible login box.
No. Normal logins look completely normal. The captcha appears as the recovery path after a lockout — a quick check that you're human, not a routine hoop.
They stop different things. Login limits stop guessing; 2FA stops a correct stolen password. Both are included in the plugin — use both.
They're layers, not duplicates. Bot protection convicts bad actors across the 400,000-site network before they guess here; login limits catch whoever still gets through. Together they end the siege from both ends.
The opposite. Login floods burn CPU and bandwidth; blocking them removes that load, and your real visitors get a faster site.

Your login is the most-attacked door on your site. Protected by default.

Attempt limits, captcha recovery, IP whitelist — running from the moment you connect. Your team never notices any of it.

No configuration/No timed lockouts/14-day money-back